mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-08-31 12:19:42 +02:00
Add in restrictions on automagics should be used for each type of plugin.
This commit is contained in:
@@ -150,6 +150,9 @@ class CommandLine(object):
|
||||
address, value = extension[:extension.find('=')], json.loads(extension[extension.find('=') + 1:])
|
||||
ctx.config[address] = value
|
||||
|
||||
# It should be up to the UI to determine which automagics to run, so this is before BACK TO THE FRAMEWORK
|
||||
automagics = self.choose_automagic(automagics, plugin)
|
||||
|
||||
###
|
||||
# BACK TO THE FRAMEWORK
|
||||
###
|
||||
@@ -176,6 +179,23 @@ class CommandLine(object):
|
||||
# Construct and run the plugin
|
||||
text.QuickTextRenderer().render(constructed.run())
|
||||
|
||||
def choose_automagic(self, automagics, plugin):
|
||||
"""Chooses which automagics to run, maintaining the order they were handed in"""
|
||||
plugin_category = plugin.__module__.split('.')[2]
|
||||
vollog.info("Detected a {} category plugin".format(plugin_category))
|
||||
output = []
|
||||
for amagic in automagics:
|
||||
if plugin_category == 'windows':
|
||||
if amagic.__class__.__name__ in automagic.windows_automagic:
|
||||
output += [amagic]
|
||||
elif plugin_category == 'linux':
|
||||
if amagic.__class__.__name__ in automagic.linux_automagic:
|
||||
output += [amagic]
|
||||
else:
|
||||
return automagics
|
||||
vollog.info("Restricting automagics to: {}".format([x.__class__.__name__ for x in output]))
|
||||
return output
|
||||
|
||||
def populate_requirements_argparse(self, parser, configurable):
|
||||
"""Adds the plugin's simple requirements to the provided parser
|
||||
|
||||
|
||||
@@ -16,6 +16,18 @@ from volatility.framework.configuration import requirements
|
||||
|
||||
vollog = logging.getLogger(__name__)
|
||||
|
||||
windows_automagic = ['ConstructionMagic',
|
||||
'LayerStacker',
|
||||
'NlpDtbfinder',
|
||||
'WintelHelper',
|
||||
'KernelPDBScanner']
|
||||
|
||||
linux_automagic = ['ConstructionMagic',
|
||||
'LayerStacker',
|
||||
'LinuxSymbolCache',
|
||||
'NlpDtbfinder',
|
||||
'LinuxSymbolFinder']
|
||||
|
||||
|
||||
def available(context):
|
||||
"""Returns an ordered list of all subclasses of :class:`~volatility.framework.interfaces.automagic.AutomagicInterface`.
|
||||
|
||||
Reference in New Issue
Block a user